Forum Discussion
Neal_Maxwell
Nimbostratus
Nov 18, 2009Load Balacing Solution in ISP Environment
I have a query about a Load Balancing solution in a ISP environment using Big-IP.
The proposed solution is for load balancing across a HTTP Cache Farm. There are 2 gateway paths in the ISP's network with Allot Service Gateways doing deep packet inspection on each path. If traffic traverses out one path it will return via the same path, so symmetry is ensured.
The requirement is to effectively terminate a cache farm with F5 load balancers in front. The Allot service gateways will redirect HTTP traffic to the Load balancer/s which will then use a Hash based URI load balancing algorithm across the Blue Coat caches.
The challenge with the solution is that the Allot Service Gateways pass traffic on Layer 2 and not via IP, so traffic will effectively be redirected on the Allot out the interface the F5 terminates on.
This means that the F5's don't have an IP to route traffic back out on, so we will be relying on Auto Last_Hop.
My question is, with the load balancers having a link to both Allot devices, will Auto Last hop ensure that traffic is returned to the correct allot box on traffic return?
My other question is, with the Blue Coats effectively being a proxy, a new connection is made out to the Web Server from the Blue Coats when a request from a client comes in. How do we ensure that this new connection traverses out via the same Allot device that the client request came in on?
I suspect that with the use of VLAN's on the F5's we would somehow be able to find a solution for this?
The Blue Coats also have to spoof the client IP, because the Client source IP has to be preserved, so SNAT is not an option on the F5's.
Any assistance would be greatly appreciated.
Diagram Attached.
- Neal_Maxwell
Nimbostratus
Bigger Diagram
Recent Discussions
Related Content
DevCentral Quicklinks
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com
Discover DevCentral Connects